Vulnerability Name: | CVE-2013-6492 (CCN-95215) | ||||||||||||||||||||||||||||
Assigned: | 2013-12-11 | ||||||||||||||||||||||||||||
Published: | 2013-12-11 | ||||||||||||||||||||||||||||
Updated: | 2014-02-18 | ||||||||||||||||||||||||||||
Summary: | The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request. | ||||||||||||||||||||||||||||
CVSS v3 Severity: | 6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
| ||||||||||||||||||||||||||||
CVSS v2 Severity: | 5.8 Medium (CVSS v2 Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P) 4.3 Medium (Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
4.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N/E:U/RL:OF/RC:C)
4.3 Medium (REDHAT Temporal CVSS v2 Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||
Vulnerability Type: | CWE-264 | ||||||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||||||
References: | Source: CONFIRM Type: UNKNOWN http://bugs.centos.org/view.php?id=6825 Source: MITRE Type: CNA CVE-2013-6492 Source: CCN Type: RHSA-2014-0174 Important: piranha security update Source: REDHAT Type: UNKNOWN RHSA-2014:0174 Source: CCN Type: RHSA-2014-0175 Important: piranha security and bug fix update Source: REDHAT Type: UNKNOWN RHSA-2014:0175 Source: CCN Type: Red Hat Documentation Web site Starting the Piranha Configuration Tool Service Source: CCN Type: Red Hat Bugzilla Bug 1043040 (CVE-2013-6492) CVE-2013-6492 piranha: web UI authentication bypass using POST request Source: CONFIRM Type: UNKNOWN https://bugzilla.redhat.com/show_bug.cgi?id=1043040 Source: XF Type: UNKNOWN redhat-piranha-cve20136492-sec-bypass(95215) Source: CCN Type: WhiteSource Vulnerability Database CVE-2013-6492 | ||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: ![]() | ||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||
BACK |